Skip to main content

How does the Microsoft 365 license integration work?

Learn more about setting up and using the BlueTally Microsoft 365 license integration

BlueTally integrates with Microsoft 365 by adding all your subscriptions to BlueTally as licenses, checking out a seat to every employee they're assigned to, and keeping the seat's Microsoft 365 activity up to date so you can see which seats are actually being used.

The Microsoft 365 integration is part of the License Intelligence add-on. If your account doesn't have License Intelligence yet, you'll see the option to start a free 14-day trial on the Microsoft 365 integration page.

Setup

To set up the Microsoft 365 license integration, please refer to our comprehensive setup guide here. It includes screenshots and detailed instructions to help you effortlessly configure the integration in a few minutes.

Configuration

After completing the integration setup, you'll need to select how you want to configure the integration in BlueTally. Simply click the Profile icon in the top-right corner, then click the Integrations link. Navigate to the License Management section and select Microsoft 365.

Before enabling the integration, you'll need to click on the Test Connection button to ensure a successful setup. This test verifies both the credentials and permissions, ensuring they align with the setup guide and are configured correctly for the integration to function properly.

Here is the complete list of all the configuration options:

  • Microsoft Government Community Cloud (GCC): Enable this if your tenant is hosted on the microsoft.us domain. You'll find this toggle in the Connection card, between the OAuth 2.0 token endpoint (v2) field and the Test Connection button.

  • Default Location: The location that new licenses from Microsoft 365 are created with. This is set once when the license is first created, so you can change a license's location afterwards without the sync overwriting it.

  • Default Department: The department that new licenses from Microsoft 365 are created with. Like the location, it's only applied when the license is first created.

  • Inactive Threshold: If a person hasn't been active in Microsoft 365 for this many days, all of their assigned seats are marked Inactive. The default is 90 days, and you can set anything from 1 to 365 days.

  • Onboarding Grace: Microsoft 365 accounts created within this many days are not marked Inactive, even if they have no activity yet. This keeps new starters out of your reclaim list while they're still getting set up. The default is 60 days, and you can set it to 0 to turn the grace period off.

  • Category Mapping: Decides which category each license lands in. See the sections below. Please note that this only appears after you've enabled the integration.

What the integration creates in BlueTally

The integration creates a License entry for every paid, user-assignable subscription in your tenant, and then checks it out to each person that subscription is assigned to. For example, let's say you have a Microsoft 365 E3 subscription with 100 purchased seats, 94 of which are assigned. The integration will then create:

  • 1x Category with the name Microsoft 365*

  • 1x Manufacturer with the name Microsoft

  • 1x License with the name Microsoft 365 E3 and 100 seats

  • 94x Seats, checked out to the matching employees in BlueTally

*BlueTally allows you to set up custom Category Mapping, or you can follow the default mapping options. See the sections below to use whatever works best for you.

The following details are synced onto each license. Seats, assigned seats, status, renewal date, SKU and included services are refreshed on every sync. Name is set on first sync (the friendly product name, e.g. "Microsoft 365 E3" rather than "SPE_E3") and is not overwritten if you've renamed the license.

  • SKU

  • Seats (purchased seats)

  • Assigned seats

  • Status

  • Renewal date

  • Included service plans and their status

  • Subscription created date (used as the purchase date on first sync)

Because Microsoft owns this data, the Number of Seats and Renewal Date fields can't be edited in BlueTally, seats can't be manually checked out or checked in, and the license can't be deleted while the integration is enabled. Everything else - including the name, category, location, department and price - is yours to edit.

You'll see a small Microsoft 365 icon next to the license name in the licenses table and on the Show License page. On the About tab, the same badge sits next to the Renewal Date to show that Microsoft owns that field.

Which subscriptions are synced

Not every subscription in a tenant is worth tracking as a paid license, so the integration deliberately skips:

  • Subscriptions that aren't assigned to users (tenant-level SKUs)

  • Deleted subscriptions

  • Free SKUs, such as the free Power BI, Teams Exploratory and Microsoft Entra ID Free plans

  • Trial subscriptions

  • Subscriptions with 0 purchased seats

If a subscription you're paying for isn't showing up in BlueTally, get in touch and we'll take a look at it with you.

Custom Category Mapping

You can set rules and other options to decide exactly which category each license belongs to during the initial import and for every sync that comes after using our Category Mapping feature. Simply find the Category Mapping row in the Microsoft 365 section of your BlueTally settings, and click Manage Category Mapping.

You can use the following mapping options:

  • Set a default category: pick the category new licenses should land in by default. If you don't set one, the integration keeps the existing behavior and falls back to a category named "Microsoft 365".

  • Name-based mapping rules: Build rules that match on the license name - contains, equals, starts with, or ends with - and route matches to the category of your choice (e.g. license name contains "Visio" → Design Software). Rules take priority over the default, and you can reorder them to control which one wins.

  • Apply to existing licenses: If you've already synced some or all of your subscriptions, one click re-categorizes all existing licenses from Microsoft 365 to match your current default and rules, lining up your existing licenses with future syncs.

Default Category Mapping

If you choose not to set up any Category Mapping settings, all the licenses you import from Microsoft 365 will automatically have the Category "Microsoft 365". However, you can change the categories of these licenses to any category of your choice, and the integration won't overwrite it.

Setting your prices

Microsoft does not disclose what you actually pay for a subscription through the API, so BlueTally can't sync your prices. To get spend, renewal value and savings figures out of the integration, you'll need to enter your prices once in the Prices card on the Microsoft 365 integration page.

For each license you enter:

  • Price per seat: what one seat costs on a single invoice.

  • Billing interval: how often that invoice is issued (Monthly, Quarterly or Annually).

So a license billed monthly at $30/user/month is a price per seat of 30 with a Monthly interval. The same license billed quarterly is 90 with a Quarterly interval, and billed annually it's 360 with an Annually interval. There's also a single Currency selector for all of your Microsoft 365 licenses.

The card shows you how much of your estate you've priced ("Priced 6 of 14 licenses, covering 1,240 of 1,600 purchased seats (78%)"), so we recommend starting with the licenses that have the most seats.

Finding the Microsoft 365 details

Once a license has been synced from Microsoft 365, open the About tab on the Show License page.

A Microsoft 365 card sits on the right, with the Microsoft 365 logo in the header and the details Microsoft owns about this subscription:

  • Status

  • SKU

  • Subscription created

  • Included services (every service plan in the subscription and whether it's Active, Disabled or Pending). These start collapsed, with the count on the toggle (for example, "12 included services").

The card also has an Open in Microsoft 365 button in the header that takes you to that subscription in the Microsoft 365 admin center.

Seat statuses

At the top of a synced license, in the page header - you'll find a seat breakdown bar that splits every purchased seat into one of five states:

  • Active: Deployed to an employee in BlueTally who has been active in Microsoft 365 within your Inactive Threshold, whose Microsoft 365 account is still within the onboarding grace period, or who is marked as a service account in BlueTally.

  • Inactive: Deployed to an employee in BlueTally who hasn't been active in Microsoft 365 within your Inactive Threshold, whose account is past the onboarding grace period, and who isn't marked as a service account.

  • Offboarding: Deployed to an archived employee in BlueTally. Unassign their license in Microsoft 365 to free up the seat, and BlueTally will check it in automatically.

  • Unmatched: Assigned in Microsoft 365 to someone who has no employee record in BlueTally. Add them as an employee and BlueTally will check this seat out to them automatically on the next sync.

  • Unassigned: A paid seat that isn't assigned to anyone in Microsoft 365.

Active, Inactive and Offboarding in the legend take you to the Deployed tab with that filter applied. Unmatched opens a list of the Microsoft 365 addresses that have no matching employee. Unassigned is shown in the breakdown but isn't a filter. If you've entered a price, the Inactive, Offboarding and Unassigned figures also show you what those seats are costing you.

Activity data on each seat

The Deployed tab on a synced license has two extra columns: M365 Status (Active or Inactive) and Last M365 activity. Clicking a seat opens the full seat details, including a Microsoft 365 section that tells you which signal the activity date came from. If the seat is Active because of the onboarding grace period or a service-account flag, that note is shown here too.

Activity is based on the person's Microsoft 365 usage as a whole, not this license specifically. BlueTally uses the most recent of:

  • Their last successful sign-in

  • Their last activity in Exchange, OneDrive, SharePoint, Teams or Viva Engage

BlueTally also reads whether the Microsoft 365 account is disabled, which counts as reclaimable no matter what the activity data says.

Service accounts

Shared mailboxes, room and equipment mailboxes and admin accounts never sign in interactively and produce no usage rows, so activity data can never show them as used. To keep them out of your Inactive count, open the employee in BlueTally, edit them, and enable the Service account toggle. Their seats will always count as Active, with a "Service account" note on the seat.

The Subscription Report

Once your subscriptions are synced and priced, the Subscription Report (found under Reports in the top navigation bar) gives you three views of them:

  • Summary: what every license costs per year and how much of it is actually used, grouped by license, department, location or category.

  • Renewals: every renewal date on a timeline, with what's at stake for each one.

  • Optimizations: every recoverable seat, ranked by annual saving.

The Optimizations tab turns the sync data into concrete recommendations, grouped into four savings categories:

  • Offboarding: seats still assigned to employees you've archived in BlueTally.

  • Inactivity: seats belonging to a disabled Microsoft 365 account, or to someone with no activity inside your Inactive Threshold.

  • Rightsizing: someone holding two Microsoft 365 licenses where everything the second one enables is already included in the first.

  • Unassigned Seats: paid seats nobody is using, with a suggested new seat count.

Since these figures are based on the prices you enter, a license with no price set won't produce any recommendations.

Updating your integration

Once the integration is enabled, you can update the connection without disabling it, and adjust all configuration settings.

When testing a new connection, the new one will be temporarily applied. If the connection succeeds, the new configuration will automatically overwrite the existing one. If it fails, your current settings will remain unchanged.

If there's an issue with your connection (e.g., an expired secret), the status card at the top of the section will show a Connection Error, and you'll also see a warning on each synced license telling you when the data was last updated. To resolve the issue, click Update Connection, enter your new credentials, and click Test New Connection.

Disabling the integration

You can disable the integration at any time with the Disable button in the status card at the top of the section. Your synced licenses, seats and history all stay in BlueTally - they just stop being updated. Seats, renewal date and seat assignments stay locked (they were created from Microsoft 365), but you can delete the license. Your stored credentials are removed, so you'll need to enter them again if you re-enable the integration later.

Frequently Asked Questions

How often does the sync run?

The sync runs every 10 minutes. If you have a lot of users in your Microsoft 365 tenant, an individual sync can take a bit longer than 10 minutes to complete. The first sync also takes longer than the rest, as every license and seat is being created for the first time.

Is the sync two-way, or can any changes be made in my Microsoft 365 tenant from BlueTally?

No, all our integrations are strictly one-way only (from Microsoft 365 to BlueTally), so you're never risking any changes being made in your Microsoft 365 tenant by our systems. Reclaiming a seat is always done in Microsoft 365 - unassign the license there, and BlueTally will check the seat in automatically on the next sync.

How does BlueTally match Microsoft 365 users to my employees?

By email address. BlueTally looks at the user's Microsoft 365 mail address first, and falls back to their userPrincipalName if the mail address doesn't match anything. Whichever it matches, it has to be the exact address on an Employee entry in BlueTally.

Some seats show as Unmatched. How do I fix that?

Those people hold a license in Microsoft 365 but have no matching Employee entry in BlueTally. Click Unmatched in the seat breakdown on the license to see the full list of addresses, add those people as employees under the Employees page, and their seats will be checked out to them automatically on the next sync.

Why are my licenses named things like "SPE_E3"?

BlueTally translates Microsoft's SKU part numbers into their friendly product names using Microsoft's own published SKU reference. If you come across a name that hasn't been translated, let us know the SKU and we'll add it. In the meantime, you can rename the license yourself - the sync won't overwrite a name you've set.

Can I change the seat count or renewal date of a synced license?

No, those two fields are owned by Microsoft 365 and are kept in sync, so they can't be edited in BlueTally. You'll see a Microsoft 365 badge next to Renewal Date on the About tab for the same reason. Change the subscription in your Microsoft 365 admin center and BlueTally will pick it up on the next sync. Every other field on the license is editable.

Why doesn't the Optimizations tab show any savings?

Savings are calculated from the price per seat you enter in the Prices card on the integration page. Until a license has a price, BlueTally can't put a number on its seats, so it won't appear in the report.

Why are my new starters showing as Inactive?

They shouldn't be, as long as the Onboarding Grace setting is turned on. Accounts created inside that window are never marked Inactive, even with no activity yet. If new starters are still showing as Inactive, check that Onboarding Grace isn't set to 0 days.

A shared mailbox is showing as Inactive. How do I stop that?

Edit the employee in BlueTally and turn on the Service account toggle. Service accounts always count as Active, so they won't show up in your Inactive count or in the Optimizations tab of the Subscription Report.

Why do some seats have no activity data?

There are two common reasons. First, sign-in data comes from Microsoft Entra ID and requires an Entra ID P1 or P2 license in your tenant - without it, BlueTally can only use the app and service usage reports. Second, the usage reports are anonymized by default in Microsoft 365. Make sure the "Conceal user, group and site names in all reports" option is unchecked in your Microsoft 365 admin center (step 22 of the setup guide) and that the Reports.Read.All permission has been granted.

How far back does the activity data go?

Microsoft's usage reports cover the last 90 days. If someone hasn't used any Microsoft 365 service in that window, their seat shows no activity date and counts as Inactive once they're outside the onboarding grace period.

Are trial subscriptions and free plans included?

No. Trials, free SKUs, tenant-level entitlements and very large (10,000+ seat) SKUs are all skipped, since they aren't seats you're paying for per person.

Does the integration pull Location and Department data for my licenses?

Not from Microsoft 365. A license gets the Default Location and Default Department you configured when it's first created, and you can change them at any time afterwards. The Location and Department shown against each seat come from the assigned employee's own record in BlueTally.

Can I see what the integration has changed?

Yes. Every license creation, name, seat, renewal date and status change, and every automatic seat checkout and check-in, is written to the license's Change Log tab by a system user called "Microsoft 365".

Can I connect multiple Microsoft 365 tenants to my BlueTally account?

That isn't possible, unfortunately. Each BlueTally account can only have one Microsoft 365 tenant connected to it via the integration; however, if you are using multi-tenancy, you can create a sub-tenant and connect it to a different tenant!

Can I still connect my Microsoft 365 tenant to BlueTally if I'm using Microsoft Government Community Cloud (GCC)?

Yes! You'll just need to make sure that you toggle on the option specifically for Microsoft Government Community Cloud (GCC) if your instance is hosted on the microsoft.us domain. You'll find this option in the Microsoft 365 section of your BlueTally account settings, between the OAuth 2.0 token endpoint (v2) field and the Test Connection button.

What happens to my licenses if I disable the integration?

They stay in BlueTally with all their seats and history intact, they just stop being updated. You can delete them, but seats, renewal date and seat assignments stay locked.

Did this answer your question?